We're running Splunk 4.3.3. One of our customers would like to export the search results (approx. 300 events) over AllTime in raw-format. The UI export fails with an error message:
File not found
Firefox can't find the file at https://pspka028:7020/splunk/en-US/api/search/jobs/1358949211.44213/event?isDownload=true&timeFormat....
This seems to be a known problem, I found some similar questions on splunkbase but did not find an answer. Are there any updates regarding this?
Same error here. Splunk 6.2.3 (264376) on Windows.
When you extend your searchstring with
| table _raw | outputcsv output.csv
you can find you exprted results in $SPLUNK_HOME/var/run/splunk.
same issue for us. any workaround?